EU AI Act takes effect, but fines for many companies are delayed until 2027

Published:

EU AI Act takes effect, but fines for many companies are delayed until 2027
Photo: Markus Schreiber/AP/TT

Today, new parts of the EU's AI Act come into force. It is a package of laws, guidelines and approaches that, among other things, will make it easier for individuals to understand whether they are interacting with an AI service.

The package, the first substantial one of its kind, is however large and complex, which means that the EU does not intend to pull out the hammer and start swinging it immediately. Different parts of the package will be implemented at different dates.

Some parts, including labelling if someone is interacting with an AI service, come into effect now. Other parts, such as potentially hefty fines for companies that engage in “high-risk AI” and fail to behave, are being postponed until 2027.

Political risk-taking

The EU's view on AI is a sensitive issue, with critics arguing that a cautious stance risks leaving the Union on the platform as the train towards the future moves on.

The political tariff war between US President Donald Trump and the EU is partly fueled by Trump's anger over the EU fining American tech companies that the EU believes have not followed the Union's rules.

Supporters of the EU's more cautious AI stance often highlight individual, glaring incidents where AI has "lost control" as evidence that stricter regulations are good.

A couple of days ago, they got their money's worth when a so-called AI agent, an autonomous AI program, "escaped" onto the internet when OpenAI (ChatGPT) tested it in a local environment without access to the public network.

Voluntariness and fines

Parts of the AI Act are based on voluntary compliance and a "code of conduct", with many of the world's largest tech companies already saying they intend to follow the guidelines - including Google, Amazon, Microsoft, OpenAI and Anthropic.

However, Elon Musk's X has only agreed to the security part of the "code" and Meta (Facebook and Instagram) has so far not signed at all.

Exactly how effective the EU regulatory package will be remains to be seen. Technically, companies that fail to comply with the directives could be fined, in theory up to as much as three percent of the company's global annual turnover.

Violations can range from failing to label AI-generated content to violating the ban on uncontrolled scraping of video footage to create a facial recognition database.

The AI Act has also been included in the EU's "omnibus" work, where various areas are being reviewed for reduced bureaucracy and simpler rules.

The EU's new AI laws divide the technology and its impact into four risk categories.

Unacceptable risk is when AI is "considered to pose a threat to people's safety, livelihoods and rights" and will be prohibited. For example, AI systems for "social scoring".

AI systems used in critical infrastructure, education, employment, or in connection with migration, asylum and border control are considered "high risk." These AI systems will be subject to "strict obligations" before they are released to the market. Law enforcement is considered to be at this risk level.

"Limited risk" refers to, for example, chatbots, where one requirement is that users should be aware that they are interacting with a machine. "Minimal risk" should allow free use, such as in AI-supported video games or spam filters.

Loading related articles...

Tags

Author

TT News AgencyT
By TT News AgencyEnglish edition by Sweden Herald, adapted for our readers

Keep reading

Loading related posts...